New review

Target

HTTP/HTTPS only
Scan profile

Normalized findings—not page bodies or cookie values—are sent to OpenAI for report writing when an API key is configured. API requests use store: false.

What this does not prove

Black-box automation cannot establish secure authorization, authentication, business logic, source code, dependencies, cloud configuration, or authenticated API behavior. Report marks these areas Not tested instead of guessing.